MALICIOUS — CRITICAL
tw-wallets[.]org
PhishDestroy identifies tw-wallets.org as a recently activated crypto drainer domain designed to trick users into unknowingly transferring cryptocurrency to threat actor-controlled wallets.
- VirusTotal
- 4/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tw-wallets.org — Контент недоступний (HTTP 502). Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 4/91 (ChainPatrol, CRDF, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies tw-wallets.org as a recently activated crypto drainer domain designed to trick users into unknowingly transferring cryptocurrency to threat actor-controlled wallets. The site mimics legitimate wallet interfaces, prompting victims to connect their crypto wallets under false pretenses, such as verifying account balances or processing transactions. Once connected, the drainer silently initiates unauthorized transfers to its own addresses, exploiting the victim's active wallet session. Users visiting this domain may experience unexpected balance deductions or transaction confirmations without their consent, a hallmark behavior of this attack vector. This domain was flagged for its role in crypto drainer campaigns and exhibits several suspicious technical indicators. VirusTotal currently shows 0 detections out of 95 sandbox and antivirus engines as of the latest scan, while the domain was registered on May 02, 2026, through Global Domain Group LLC. The infrastructure relies on Let’s Encrypt for SSL certification, which is often leveraged by malicious actors to establish trust with visitors. The domain resolves to the IP address 188.114.96.3, a hosting provider known for accommodating fraudulent services. These factors combined raise significant red flags about its legitimacy and intent, despite the absence of immediate antivirus detections. If you have visited tw-wallets.org or entered any wallet credentials, disconnect your wallet immediately from the site and revoke any unauthorized permissions through your wallet’s settings or interface. Transfer any remaining funds to a newly generated wallet address not associated with the suspicious domain, and monitor your transaction history for unfamiliar activity. Report the domain to your wallet provider and consider filing an incident report with local cybercrime units or platforms like the FBI’s IC3 or Chainalysis Reactor. Use ad-blockers and browser extensions like MetaMask’s phishing detection to block similar domains in the future, and always verify URLs manually before interacting with wallet-related websites. Staying vigilant against social engineering tactics such as fake airdrops or urgent transaction prompts can help prevent falling victim to crypto drainers.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | tw-wallets.org |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 5 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of tw-wallets.org · checked May 6, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260506-A78483 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.